CVE-2014-2642: Input Validation
Published Oct 2, 2014
·Updated
HP System Management Homepage (SMH) before 7.4 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
Affected Software
5 affected components
HP System Management Homepage<=7.3
HP System Management Homepage=7.0
HP System Management Homepage=7.1
HP System Management Homepage=7.2
HP System Management Homepage=7.2.1
Event History
Oct 2, 2014
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-2642?
CVE-2014-2642 is classified as a medium severity vulnerability due to its potential for clickjacking attacks.
2
How do I fix CVE-2014-2642?
To mitigate CVE-2014-2642, upgrade to HP System Management Homepage version 7.4 or later.
3
What systems are affected by CVE-2014-2642?
CVE-2014-2642 affects HP System Management Homepage versions prior to 7.4, including versions 7.0, 7.1, 7.2, and 7.3.
4
What type of attack does CVE-2014-2642 facilitate?
CVE-2014-2642 facilitates clickjacking attacks, allowing remote attackers to manipulate a user's interaction with the application.
5
Is CVE-2014-2642 easy to exploit?
CVE-2014-2642 can be relatively easy to exploit for attackers familiar with clickjacking techniques.